﻿using System;
using System.Collections.Generic;
using System.Linq;
using System.Web;
using System.Web.UI;
using System.Web.UI.WebControls;
using System.Data;

namespace OWASP.DotNetGoat
{
    public partial class SQLInjection : System.Web.UI.Page
    {
        protected void Page_Load(object sender, EventArgs e)
        {

        }

        protected void btnFind_Click(object sender, EventArgs e)
        {
            DatabaseUtilities du = new DatabaseUtilities();
            DataSet ds = du.CheckMailingListEmailAddress(txtEmail.Text);
            if (ds.Tables[0].Rows.Count > 0)
            {
                lblOutput.Text = "You are already on the list!";
                grdEmail.DataSource = ds;
                grdEmail.DataBind();
            }
            else 
            {
                
                bool result = du.AddToMailingList(txtFirst.Text, txtLast.Text, txtEmail.Text);
                if (result == true)
                    lblOutput.Text = "You have been added!";
                else
                    lblOutput.Text = "Oops, an error occurred - you were NOT added to our mailing list.  Please try again";
            }
        }
    }
}